Kimsuky Group Using Meterpreter to Attack Web Servers

2023-05-21 Ahnlab

https://asec.ahnlab.com/en/53046/

Thumbnail for Kimsuky Group Using Meterpreter to Attack Web Servers

ASEC describes Kimsuky attacks against a Windows IIS web server at a Korean construction company, shifting from the group’s usual document-based spear phishing to exploitation of poorly managed or unpatched web servers. After breaching the IIS process, the actor executed PowerShell to download a Metasploit Meterpreter backdoor from 45.58.52[.]82 and then used Meterpreter to install additional proxy malware. The Meterpreter stager and proxy tool were written in Go, and the DLL payload ran through regsvr32.exe, a method ASEC says matches prior Kimsuky tradecraft. The proxy component relayed IP and port pairs and used an “aPpLe” communication signature, likely to support later RDP access to the compromised server.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.58.52.82 2023-05-15 2023-11-01
HASH 6b2062e61bcb46ce5ff19b329ce31b03 2023-05-15 2023-05-21
HASH 000130a373ea4085b87b97a0c7000c86 2023-05-15 2023-05-21

Related Actors

Related Reports

« Back